See whether your CAA record change has spread: 12 public resolvers, queried live, side by side.
Map key: each dot is the country where a resolver's operator is headquartered (number = resolvers), coloured by result. It does not show where the query ran — most of these resolvers are anycast networks with servers in many cities.
These are 12 large public resolvers, queried live over encrypted DNS-over-HTTPS from our servers. Most are anycast networks with many locations, so we show which resolver answered — not a city. Two (CIRA Canadian Shield) are run by the organization that operates .ca. Your ISP's resolver may still show an older answer until its cache expires.
CAA records declare which certificate authorities (for example Let's Encrypt) are allowed to issue SSL certificates for your domain. Publishing a wrong CAA record can stop certificate issuance or renewal.
Type your domain in the box above, keep CAA selected and press Search. We ask 12 public DNS resolvers — including two run by CIRA Canadian Shield — at the same moment and show each answer side by side.
Green rows should show your CAA entries (for example 0 issue "letsencrypt.org"). "No CAA record" is also valid — it means any CA may issue. Before requesting a certificate, make sure the CA you use appears on every row.
No, but it is a good security practice and some hosts add one automatically.
The issuing CA is probably not allowed in the CAA record, or the change has not propagated to the CA yet.
Governed by the TTL of the previous CAA record.